Administration

Team roles and permissions

Decide who can send, who can spend and who can see each client's data.

Where this lives. Sign in and open /staff/team in the app.

What it does

In emailcampaign.ai (Campaign Cloud, in the signed-in app's own sidebar), two different things share the word "staff" or "roles," and they don't overlap. Staff & privileges (/staff/team) is for platform-side people — support agents, assistants, ops managers who work across customer accounts, not inside one workspace. Every page under /staff checks this on load and bounces anyone who isn't platform staff back to their own Command Center. Each staff member holds one or more of eight privileges — Support desk, Billing operations, Provisioning & servers, Website content, Deliverability ops, Account security, Copilot supervision, and Manage staff — and can be scoped to specific customer accounts or left unscoped for every account. The owner holds every privilege and can't be edited here. A staff member needs at least one privilege at all times; removing the last one isn't allowed — deactivate them instead. Two-factor is required before any staff tool can be used, and an admin can force this per person with a "Require two-factor" checkbox that shows as "2FA required — not enrolled" until they set it up.

Roles & permissions, by contrast, is under Settings and governs your own workspace's members. The system ships 12 fixed roles (owner, admin, manager, operator, sales rep, deliverability manager, caller, contract manager, finance, analyst, viewer, auditor), each with its own permission set. You can clone any of them into a custom role, rename it, and toggle individual permissions in two groups: Baseline (reading and day-to-day work) and Sensitive (money, sending, live DNS, provisioning, exports, deletion — always checked server-side). The grant rule is simple and enforced on the server: you can only hand a permission to someone else if you hold it yourself, and every role keeps "view dashboard" so its holder can at least open the workspace. Saving a role's permissions applies to everyone holding it immediately; a role can only be deleted once nobody is assigned to it.

Inviting people is also two separate flows. A staff invite (Staff & privileges page) sets capabilities and account scope up front and sends a single-use link valid 7 days; a brand-new recipient gets a staff account, never a customer workspace or trial, while an existing account holder is simply granted staff access on acceptance. A workspace teammate invite (Settings > Members) is simpler — just an email and one of the 12 roles — also a 7-day link, with the accept link shown on-screen as a fallback if the invite email doesn't send.

Support SLAs live in the staff support desk, not in a settings page you can edit: the default first-response targets are Low priority 72 hours, Normal 24 hours, High 4 hours, and Urgent 1 hour, with tickets auto-assigned to the least-loaded agent. A ticket shows "due in" or "overdue" against that clock until someone replies.

Before you start

  • Inviting or editing staff needs the "Manage staff" privilege (or ownership); inviting workspace teammates and editing roles need the "manage users" permission.
  • Two-factor is mandatory for staff tools — an invited staff member cannot use any staff page until they enroll.
  • [VERIFY: whether the support SLA hours (72/24/4/1) can be changed per workspace anywhere outside this codebase review — no settings UI for it was found]

Set it up, step by step

  1. For platform staff: open Staff & privileges, fill in email and title, check at least one privilege, optionally limit Accounts this person may work on, and click Send invitation.
  2. For a workspace teammate: go to Settings > Members, enter their email, pick a role, and click Send invite.
  3. To build a custom role: open Settings > Roles & permissions, choose an existing role to base it on, name it, toggle permissions, and save.
  4. To require two-factor for a specific staff member, check Require two-factor on their row.
  5. Revoke any pending invitation (staff or teammate) from its list before it's accepted if plans change.

What you should see

An owner's row always shows "owner · all privileges" with no edit controls. A staff member with 2FA not yet enrolled shows a red "2FA required — not enrolled" pill instead of green. A custom role's permission checkboxes you don't personally hold appear disabled with a tooltip explaining why.

Common problems

  • You can't check a permission when editing a role. You don't hold that permission yourself — only permissions you have can be granted to others.
  • Deleting a role fails. Someone is still assigned to it; move them to a different role first.
  • A new staff member can't do anything after accepting. They haven't enrolled two-factor yet — required before any staff tool works.

Common questions

What is the difference between a workspace member and platform staff?

A member works inside one workspace and sees only its data. Platform staff operate the platform itself across workspaces, which is why staff accounts carry a two-factor requirement that ordinary members do not.

How should an agency scope access?

Give each person the narrowest role that lets them do their job, and scope client access deliberately. The question to ask of any role is not what it allows but what it would cost if that account were taken over.

Last updated September 19, 2026. Written by the team that operates the platform.

Team Roles and Permissions: Who Can Send, Spend and See What